I am doing weekly statistics and in splunk 7, i can easily specify the first day of a week by @w1 so 1 means Monday.
While I found I am not able to do it in Splunk 6.4, it always uses Sunday as the first day of a week.
I am wondering if there is a way in Splunk 6 to do @w1?
I do not have 6.4 version to test this, But try adding this before your stats or timechart command -
| eval _time=relative_time(_time,"@w1") | timechart span=1w ....
OR try this -
https://answers.splunk.com/answers/562033/why-is-time-chart-with-span-of-1w-always-thursday.html
Please accept as answer if this would solve your case.